GHSA-wpv7-x588-92g9High

Joomla Extension - icagenda.com - Authenticated Stored XSS in iCagenda 4.0.8 to 4.0.12 - The...

Published
August 20, 2026
Last Modified
August 20, 2026

🔗 CVE IDs covered (1)

📋 Description

Joomla Extension - icagenda.com - Authenticated Stored XSS in iCagenda 4.0.8 to 4.0.12 - The frontend "Submit an Event" form stores the image and file fields as raw strings with no output-side HTML-attribute escaping.

🔗 References (3)